Skip to main content

CWE archive

CWE-97 CVEs

Programmatic archive

7 CVEs tagged with CWE-970 Critical, 6 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-53934

Published Dec 18, 2025

A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requests to the GetResource handler. Improper input validation…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36558

Published May 1, 2025

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with a PiCtor…

CVSS 5.1 · Medium

CVE-2025-35996

Published May 1, 2025

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is late…

CVSS 8.5 · High

CVE-2025-21103

Published Feb 17, 2025

Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7 contain(s) an improper neutralization of server-side vulnerability. An unauthen…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-56363

Published Dec 23, 2024

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, t…

CVSS 7.8 · High

CVE-2024-37621

Published Jun 17, 2024

StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shippingOptionConfig/index.blade.php.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29686

Published Mar 29, 2024

Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1